Who I Help · Private Equity

Cybersecurity for private equity firms and their healthcare portfolio companies.

Two numbers have been moving in opposite directions for a decade, and where they crossed is the most under-priced risk in healthcare private equity right now.

OCR resolutions land roughly five years after the underlying incident. Average North American buyout holds reached 7.1 years by 2023. The enforcement lag now fits comfortably inside your hold period.

Five years
Roughly the distance between a healthcare organization's security failure and the day a regulator puts a number on it.
Exhibit A · Why your diligence questionnaire cannot see this

Breach history is a lagging indicator, and a poor one.

Standard cyber diligence asks whether the target has experienced a breach or security incident. In a meaningful number of cases the honest answer is no and the accurate answer is we do not know.

MMG Fusion, a dental software vendor, had a December 2020 breach exposing approximately 15 million individuals. It was never reported. OCR opened its investigation in March 2023 after a complaint, by which time the data had already surfaced on the dark web. Had that company been a diligence target in 2022, management could have answered the breach question in good faith and been wrong by fifteen million records.

The question to ask instead

Has this organization ever completed an accurate and thorough security risk analysis? When, by whom, and what happened to the findings?

Every enforcement action in this area turns on that document. Ask for it by name. If it does not exist, or it is a certificate from an online portal, you have not found a gap in a control. You have found an organization that has never looked.

Exhibit B · Why healthcare portfolios are structurally worse

Three reasons the average does not apply to you.

01
The asset classes you are buying are the ones OCR is working

Physician medical groups captured a record 46% of first-quarter 2026 deal volume, with deal count up 18% year over year, and behavioral health and long-term care led market performance. Now look at who OCR settled with: a substance use disorder treatment provider, a women's health physician group, a diagnostic imaging provider, a health benefits plan, a dental software vendor. To a first approximation, the same list.

02
Aggregation multiplies a defect instead of diluting it

Ten add-ons means ten risk analyses that were never performed, ten EHR instances, ten sets of local administrator credentials, ten vendor stacks with overlapping and unmapped business associate relationships. Integration merges the networks long before it merges the controls. In an operating business a security gap is a risk. In a roll-up it is a defect you replicate at every close.

03
The clock does not reset at close

Every clock that matters runs on calendar time, not ownership time. Meanwhile consolidation, the EHR migration and revenue cycle integration all get priority, and security waits until the systems settle down. The riskiest twelve months in an acquired healthcare company's life are usually the twelve immediately after acquisition, and they are the twelve during which almost every sponsor has decided to postpone the work.

Exhibit C · Where I come in

Four points in the life of a deal.

Pre-close

Diligence that prices the risk

The risk analysis by name, its date and who performed it. A cyber maturity assessment inside the diligence window, while the finding still has price impact. Vendor concentration mapped across the portfolio. Cyber insurance checked against reality, comparing what was attested at underwriting to what is actually deployed. MFA is the routine gap.

First 100 days

Baseline and risk analysis

Baseline against the HHS Cybersecurity Performance Goals, which are free, prioritized, published by the regulator, and defensible in an LP letter in a way a vendor's proprietary maturity score is not. Complete the risk analysis, which also starts the Recognized Security Practices clock.

Across the hold

One CISO, not one per company

A portfolio company at $30 million in revenue cannot justify a full-time security leader and will not hire one. Ten of them together can justify a very good fractional one, plus a standardized policy set, a common vendor risk scoring model, one AI governance framework, and one quarterly reporting format that works for the board and the LP letter without translation.

Before exit

Getting the file clean

Buyers run diligence on you the way you ran it on the seller, and against the newer rule. Unremediated findings become price adjustments and escrow. This is the work that is cheap with eighteen months of runway and expensive with three.

Exhibit D · The July 2027 argument

The delay is not breathing room. It is the last budgeting window.

The HIPAA Security Rule overhaul slipped from a May 2026 target to roughly July 2027. Most of the industry reads that as relief. For a fund it is the opposite.

If your hold period puts an exit in 2027 or 2028, your buyer's diligence will be run against the new rule, not the current one.

HHS's regulatory impact analysis estimated the proposed changes would cost the industry roughly $9 billion in the first year and $6 billion annually thereafter. Those figures sit in a 124-page Federal Register document (90 FR 898) and are cited here as reported by Morgan Lewis and Crowell & Moring. That cost lands on operating companies, and it is either budgeted across 2026 and 2027 or absorbed in a purchase price adjustment.

The rural footprint most sponsors have not connected

For platforms with rural footprints, the CMS Rural Health Transformation Program is $50 billion over 2026 to 2030, awarded to all 50 states on December 29, 2025, with FY2026 state awards ranging from $147.3 million to $281.3 million. Cybersecurity strengthening is named among the allowable technology-infrastructure uses (CMS). State-level allocation decisions are being made now. This is a funded remediation path most sponsors have not connected to their security budget.

Exhibit E · Questions sponsors ask

Frequently asked questions

What does cyber due diligence cover in a healthcare acquisition?

The data the target holds and the obligations attached to it, whether an accurate and thorough security risk analysis exists and what happened to its findings, incident and breach history including unreported incidents, the business associate agreement chain, vendor and AI concentration, whether the cyber policy's underwriting representations match what is actually deployed, and the estimated cost and timeline to reach an acceptable posture. The output is a risk picture priced in dollars, not a control checklist.

Why does a five-year enforcement lag matter to my fund?

OCR resolutions land roughly five years after the incident. Average North American holds reached 7.1 years by 2023. A compliance failure you did not diagnose at diligence now surfaces during your hold rather than after your exit, often during integration or while a sale process is live.

What is the single question to ask a healthcare target?

Has this organization ever completed an accurate and thorough security risk analysis, when, by whom, and what happened to the findings. Ask for the document by name. Its absence is a finding, not a task for the integration plan.

Does the delayed HIPAA Security Rule help or hurt a 2027 exit?

It hurts if you treat it as breathing room. A 2027 or 2028 exit will be diligenced against the new rule rather than the current one, which makes the delay the last window in which remediation is budgeted capital expenditure rather than a purchase price adjustment.

We already have an MSP at the portfolio company. Why would we need you?

An MSP runs infrastructure. A CISO decides what risk the business accepts, owns the compliance posture, answers the auditor and the carrier, and reports to the board. Those are different jobs. I work alongside MSPs rather than replacing them.

Do you work with one portfolio company or across the platform?

Across the platform is where the economics work. A $30 million portfolio company cannot justify a full-time security leader and will not hire one. Ten of them together can justify a very good fractional one, with a standardized policy set, a common vendor risk model, and one quarterly reporting format for the board and the LP letter.

Can rural portfolio companies fund this?

Possibly. The CMS Rural Health Transformation Program is $50 billion over 2026 to 2030, awarded to all 50 states in December 2025, and cybersecurity strengthening is a named allowable use. State allocation decisions are being made now.

The number that should go in the memo is five years.

The rule is not final until July 2027. The lag is running right now, on every company you already own, from breaches that may have already happened.

Book a Free Security Clarity Session
Melissa Thornton, CISSP, C|CISO · Founder, Cybersecurity Advisory Group · White Plains, New YorkLast reviewed September 2026